Vulnerability library
Security checkMarch 27, 2026

Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmhandlebars

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

resolvePartial() in the Handlebars runtime resolves partial names via a plain property lookup on options.partials without guarding against prototype-chain traversal. When Object.prototype has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS.

Recommendation

Update the handlebars package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 4.0.0, < 4.7.9
  • Patched version(s): 4.7.9

References

Could your website be exposed too?

SmartScanner can check your website for Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 27, 2026